CVE-2022-37042
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 89% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22
מוצרים מושפעים
synacor: zimbra collaboration suite
קישורים
- https://wiki.zimbra.com/wiki/Security_Center PatchVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center PatchVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource